MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 034a4e48a40858804dcae7ae39295e1fbc7ab6c575ab66f7f6a1f15720039b20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 034a4e48a40858804dcae7ae39295e1fbc7ab6c575ab66f7f6a1f15720039b20
SHA3-384 hash: 7e4f5b1bd56f451d26d9f61273a68833c3371573e1068a8cc52f63f3d6af33198bfb68d81d2ce47797006a30f4d54fea
SHA1 hash: c24c0ddd256fbd875351bff33a6161dd41bd6924
MD5 hash: af0fb616eebed70f869ce0312376eaae
humanhash: eight-november-wyoming-jersey
File name:Quotationrequest14-05-2020_PDF.ARJ
Download: download sample
Signature AgentTesla
File size:477'733 bytes
First seen:2020-05-14 06:42:44 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:kF9tQBGLr3bZLk68StTRD56eeZBwu465U:kOB6zbZlB6eC465U
TLSH DCA423F1B09866E070D1033D00FDF9DF5E1D0FB6892A4892C44DD9395549BA7EA83AF6
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.strongmailvault.com
Sending IP: 111.90.144.227
From: info@sortilemn.com
Subject: Quotation
Attachment: Quotation request14-05-2020_PDF.ARJ (contains "Quotation request14-05-2020_PDF.exe")

AgentTesla SMTP exfil server:
mail.karcek.com.tr:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-14 05:21:13 UTC
File Type:
Binary (Archive)
Extracted files:
28
AV detection:
17 of 48 (35.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj 034a4e48a40858804dcae7ae39295e1fbc7ab6c575ab66f7f6a1f15720039b20

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments